This release has strong transparency and engineering hygiene for a newly published package: it is MIT-licensed, includes a substantial README, changelog, tests, CI, and a coherent source tree, has no install-time scripts, is not deprecated or archived, and its repository matches the package. However, it is extremely immature: v0.1.0 is the sole release, the package is effectively new, repository popularity is zero, and there is no recorded commit activity over the last three months. The absence of security scanning, a security policy, and explicit workflow token permissions adds avoidable operational risk. It may be reasonable to evaluate or adopt with caution, but it lacks the release history and maintenance evidence expected for a security-sensitive OpenID Connect dependency.
68%
Total Score
63
100
78
80
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lcobucci/jwt Version ^5.3 | — | — |
lcobucci/clock Version ^3.0 | — | — |
psr/http-factory Version ^1.1 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
league/oauth2-server Version ^9.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.